Live data from Hacker News

Tech firms seek to frustrate internet history log law

bbc.co.uk

161–170 of 170 posts

Re: Tech firms seek to frustrate internet history log law

#161
post #6

Earlier quoted context omitted.

So where is the conversation about that ? If this measure will not catch the very people it is intending to catch, what is its purpose?

I can't work out the purpose. It feels scary and Orwellian but I don't know why they want to collect all this data. Who benefits? In a totalitarian regime it makes sense because you can use it to prevent political opposition. But in this case, it's a democratic government that can easily be voted out. It doesn't help anyone cling to power. Maybe I'm over-thinking, but I can't work out the point.

Democracies can fail, for example the recent rise of Erdogan. Asshats in power want democracy to fail because when it does they will be the ones in power.

Re: Tech firms seek to frustrate internet history log law

#162
post #6
post #5

Earlier quoted context omitted.

Right. It makes no sense. "Let's bring in a law that logs everyone not seeking to avoid detection." Any serious criminal/terrorist will use a VPN, disposable phones with end to end encrypted messaging, or pen and paper. Any criminal/terrorist that doesn't take these measures shouldn't be a problem to prevent in the firstplace.

So where is the conversation about that ? If this measure will not catch the very people it is intending to catch, what is its purpose?

They're not looking for actual terrorists or criminals. They're looking for people like Occupy Wall Street protesters, who actually pose a threat (ie. redistribution of wealth) to those in power. Then as soon as they do something like pirate a movie, they can be thrown in jail (ie politically neutered).

Re: Tech firms seek to frustrate internet history log law

#163
post #99

Earlier quoted context omitted.

There doesn't seem to be a technical definition of an 'Internet Connection Record', but from the factsheet[1], they: "are records of the internet services that have been accessed by a device. They would include, for example, a record of the fact that a smartphone had accessed a particular social media website at a particular time." and: "ICRs do not provide a full internet browsing history. The ICRs do not reveal eve…

HTTP Host headers, IP addresses and HTTPS hostname negotiation headers are sufficient to meet that requirement without a doubt.

That'd work fine for HTTP(S) data, I suspect the data capture would have to be done at the IP level by default, with per-protocol filters on top to capture additional data. Which is going to add complexity to the data capture equipment, plus an ongoing maintenance cost to keep on top of new/updated protocols.

I can't see the current government accepting the possibility that the Internet Bad Guys(tm) could just use a different protocol and avoid all logging.

Re: Tech firms seek to frustrate internet history log law

#164
post #53

The logical end point, if you think it through, is scary for technology. There will be a battle for a time where legislators play cat and mouse with technology and privacy companies. But as each new hole appears, they'll invent new laws to close them off. This wouldn't be so bad except for the problem that encryption is math and short of making math illegal there will always be a hole. Factor in steganography and it…

This may be a stupid question but I've got to ask because I'm not 100% sure. Is there no practical way data can be sent and received anonymously? If no one, except the people trying to communicate, knows who encrypted or decrypted anything, how could they enforce such a law? Since a well encrypted message should be safe to broadcast, it can be sent to the whole world with only the intended recipients being able to de…

Yes, it is possible, if your attacker isn't too powerful. However, there will be a lot of tradeoffs and the software is not quite finished yet.

The software which is currently closest to this is ricochet [0] which communicates directly between Tor hidden services. Since there is no central server, there is no one to record metadata (at least in a trivial fashion). However there is still a lot of work left to do before ricochet is something that could be mainstream. Also, some metadata can be leaked, such as when one is online, and (until proposal 224 is out) how much people are communicating based on the number of lookups on the hidden service directories corresponding to the service (since there is no randomness in the system yet, afaik, you can brute force values to get into the right place in the ring. I haven't read the Tor specifications in a while tho, so I may be wrong)

You could also use some sort of mixnet system, although you would probably end up leaking who is sending messages to their ISP. To stop the ISP from determining when, you could send o constant stream of encrypted traffic, although that would be inefficient. (I need to read more research on this)

However, weather people will actually use these systems is in entirely different problem.

[0] https://ricochet.im

Re: Tech firms seek to frustrate internet history log law

#165
post #111

Pardon my extreme language but Fuck! How on earth do bills like this come to pass without uproar widespread enough to quash it. Shit like this seriously makes me want to give up on the internet and walk away from it despite it having been my lifeline and the foundation of my income since I was in my teens almost 30 years ago.

> Shit like this seriously makes me want to give up on the internet and walk away from it You echo my thoughts exactly - I've recently been thinking about moving to a small town north of where I currently live, where land prices are cheap, and you can get 10 acres for nothing. Bad part - little to no internet access. Part of me thinks that's a good thing.

That works if you can make that 10 acres work for you... I've been trying that model for the last little while on top of my full time job. I can tell you from first hand experience that while it may be rewarding, the amount of work and money it takes to get those 10 acres working for you is not trivial and has the serious probability of burning you out before you make it. I wouldn't recommend doing this on top of a full time job if time is of the essence. It's probably something you'd want to do over the period of a couple of years because trying to get 10 acres working for you inside of a year is an insane amount of work - it's literally more than a second full time job. I know this, because that's exactly what I've been doing for the last 9 months.

The shitty internet access will be beyond frustrating at first. Again, speaking from first hand experience, you will become accustomed to it and find workarounds. I sometimes think that not having any internet access at all would be easier than dealing with the outages that I deal with on a weekly basis. Eventually you stop caring about it and think fuck it, I'll just do something else with my time, read a book, go out on your land, learn useful things like small engine repair or carpentry or whatever...

Not having Internet and TV can be frustrating and boring at first, but finding hobbies and learning skills to fill that time instead can be extremely good for your confidence and your soul.

Re: Tech firms seek to frustrate internet history log law

#166

Pardon my extreme language but Fuck! How on earth do bills like this come to pass without uproar widespread enough to quash it. Shit like this seriously makes me want to give up on the internet and walk away from it despite it having been my lifeline and the foundation of my income since I was in my teens almost 30 years ago.

The reason such bills get proposed and passed is because, broadly speaking, they are popular with the electorate or at least not unpopular. The reason they are not unpopular, the root problem, is because the downsides are perceived as theoretical and in the future whereas the upsides are seen as real and in the present. Put simply the arguments against look like this: Oppose this bill because the government COULD abu…

I'm not sure if there's any truth to these anecdotes, quite probably not but I feel they're particularly poignant given the situation:

When the U.S. first decided to send man to the moon, they spent billions of dollars inventing a pen that would write in zero gravity. Meanwhile the Russians used a pencil.

Again with the race for hacking computers in the Russian Embassy to spy on the Russians, instead of spending billions of dollars securing their computers in a cyber arms race, they switched to typewriters.

I find the simplicity in their solutions to these problems remarkably satisfying.

It is this simplicity that calls me to just say fuck it, if you're going to act like that, I'm just not playing any more. I'll go do something else interesting that doesn't involve you.

Re: Tech firms seek to frustrate internet history log law

#167
post #25

Earlier quoted context omitted.

Well, if memory serves, for the most part haven't most terrorist attacks been coordinated over either completely open channels or over non-technical channels? If I remember correctly, the Bin Laden operations were orchestrated via sneakernet, the more recent attacks in France were orchestrated with check-out aisle cell phones. The technical difficulties law enforcement faces with terrorism and crime isn't that crimin…

> Well, if memory serves, for the most part haven't most terrorist attacks been coordinated over either completely open channels or over non-technical channels? If I remember correctly, the Bin Laden operations were orchestrated via sneakernet, the more recent attacks in France were orchestrated with check-out aisle cell phones. We have no way of knowing. There hasn't been a repeat attack at the scale of 9/11 to date…

If we're to go by this article [1], the TSA is only 4.3% effective.

[1] http://edition.cnn.com/2015/06/01/politics/tsa-failed-underc...

Re: Tech firms seek to frustrate internet history log law

#168

Earlier quoted context omitted.

This may be a stupid question but I've got to ask because I'm not 100% sure. Is there no practical way data can be sent and received anonymously? If no one, except the people trying to communicate, knows who encrypted or decrypted anything, how could they enforce such a law? Since a well encrypted message should be safe to broadcast, it can be sent to the whole world with only the intended recipients being able to de…

because when you send messages, they go from your computer to your ISP, then to the internet. so anyone watching you at the ISP level sees you sent something. Then, it depends where you sent it. Email goes to one person, so receipt of the message is seen on their ISP's side. Yes the encrypted message is safe to be sent to the whole world, but there is no single public folder for "the whole world". That would be too m…

Couldn't bad players just send and receive through other peoples connections, maybe even pretend to be someone else on purpose, in order to get them arrested? It's pretty trivial to jump on someone's wi-fi, and use throw away emails.

Re: Tech firms seek to frustrate internet history log law

#169

Earlier quoted context omitted.

because when you send messages, they go from your computer to your ISP, then to the internet. so anyone watching you at the ISP level sees you sent something. Then, it depends where you sent it. Email goes to one person, so receipt of the message is seen on their ISP's side. Yes the encrypted message is safe to be sent to the whole world, but there is no single public folder for "the whole world". That would be too m…

Couldn't bad players just send and receive through other peoples connections, maybe even pretend to be someone else on purpose, in order to get them arrested? It's pretty trivial to jump on someone's wi-fi, and use throw away emails.

I think it depends on what you do with someone else's connection. A criminal could definitely get an innocent person's house raided, but cops aren't stupid either. If they do their homework first and see Aunt Mildred only goes to facebook and cooking-network.com, and suddenly she's sending death threats to public officials, they might knock on her door and politely ask to put a wifi surveillance device in her home to pinpoint the intruder's signal.

Sure you could steal signals or go to starbucks (which has cameras of course ) a few times and maybe get away with it, but to do it reliably, on demand, is very difficult.

Re: Tech firms seek to frustrate internet history log law

#170
post #111

Earlier quoted context omitted.

> Shit like this seriously makes me want to give up on the internet and walk away from it You echo my thoughts exactly - I've recently been thinking about moving to a small town north of where I currently live, where land prices are cheap, and you can get 10 acres for nothing. Bad part - little to no internet access. Part of me thinks that's a good thing.

That works if you can make that 10 acres work for you... I've been trying that model for the last little while on top of my full time job. I can tell you from first hand experience that while it may be rewarding, the amount of work and money it takes to get those 10 acres working for you is not trivial and has the serious probability of burning you out before you make it. I wouldn't recommend doing this on top of a f…

I know this is a late reply and such - but my first modem was a 300 baud screamer (heh) - so a slow connection could look fast to me otherwise (not as fast as what I have currently, tho).

As far as getting 10 acres to work for me - well, I wasn't thinking that route (ie - farming). More just doing odd jobs to make the tax payment; I'm pretty good with mechanically inclined stuff - I also can work a welder, plasma cutter, grinder, etc. Or - maybe I could get a cheap 3D printer and/or laser cutter and do stuff with that.

Everything else would be completely paid off, and otherwise I'd be off-the-grid (electric from solar/wind, water from a well, then a septic tank - I guess I might have to budget for maintenance of that stuff, too).

I'm thinking, though, I might still be able to commute into jobs - where I'm thinking about locating isn't too far away from work - though it'd be a long commute (50-75 miles each way).

Post reply on HN